Salesforce Aura Campaign
Attack Intelligence
Salesforce Aura Campaign was compromised in a ransomware attack attributed to shinyhunters in March 2026. The organization, operating in the Technology sector in Unknown, was added to the group's data leak site as part of an extortion campaign.
shinyhunters operates as a financially motivated ransomware-as-a-service (RaaS) operation, exfiltrating sensitive data and threatening public disclosure to pressure victims into paying ransom demands.
Several hundreds of companies set to release with FINAL WARNINGs upon failure to comply. To all affected companies who will be or are being contacted by us ("ShinyHunters"), please consider this a preliminary warning before we release your name with FINAL WARNING or a complete data leak. Reply, engage, pay a small price, and prevent a publication. Make the right decision, don't be the next headline. | Updated: 10 Mar 2026 | Warning: NOTICE OF WARNING
Intelligence correlations link this incident to 1 vulnerability(ies) including CVE-2026-35273, which may have been leveraged as initial access vectors or for lateral movement.